Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in salubrio Add Code To Head add-code-to-head allows Stored XSS.This issue affects Add Code To Head: from n/a through <= 1.17.
Published: 2025-08-28
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Add Code To Head plug‑in fails to escape or otherwise neutralize input that is subsequently rendered in the page header, resulting in a stored cross‑site scripting vulnerability (CWE‑79). An attacker is able to inject arbitrary JavaScript that will then execute in the browsers of any visitor who views a page that includes the malicious content. The impact is that attackers can hijack sessions, deface content, or perform other malicious actions in the context of site visitors.

Affected Systems

WordPress installations that use salubrio’s Add Code To Head plugin version 1.17 or earlier. Any site where the plugin is active and accepts user‑supplied code to be placed in the head section of pages is affected. The vulnerability has no version restriction beyond the stated ceiling.

Risk and Exploitability

The CVSS score of 5.9 denotes moderate severity, and the EPSS score of less than 1% indicates a low likelihood of exploitation in the near term. The flaw is not listed in the CISA KEV catalog, which reduces the expectation of widespread active exploitation. Attackers would need access to the plugin’s administrative interface or a user who has permission to add code to the header, so the attack vector is inferred to be via this internal interface. Once injected, the malicious code runs automatically for all site visitors, making remediation a priority for any site that allows such input.

Generated by OpenCVE AI on April 30, 2026 at 15:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Add Code To Head plug‑in to version 1.18 or later, which includes the XSS fix.
  • If an immediate update is not possible, disable or uninstall the plugin to remove the source of the stored scripts.
  • After disabling or updating, audit the site’s code and database for any residual malicious scripts and remove them.

Generated by OpenCVE AI on April 30, 2026 at 15:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-26044 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in salubrio Add Code To Head allows Stored XSS. This issue affects Add Code To Head: from n/a through 1.17.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in salubrio Add Code To Head allows Stored XSS. This issue affects Add Code To Head: from n/a through 1.17. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in salubrio Add Code To Head add-code-to-head allows Stored XSS.This issue affects Add Code To Head: from n/a through <= 1.17.
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Thu, 28 Aug 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 28 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 28 Aug 2025 13:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in salubrio Add Code To Head allows Stored XSS. This issue affects Add Code To Head: from n/a through 1.17.
Title WordPress Add Code To Head plugin <= 1.17 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:56.311Z

Reserved: 2025-05-19T14:13:53.900Z

Link: CVE-2025-48314

cve-icon Vulnrichment

Updated: 2025-08-28T13:33:54.328Z

cve-icon NVD

Status : Deferred

Published: 2025-08-28T13:15:41.413

Modified: 2026-04-23T15:31:05.290

Link: CVE-2025-48314

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T15:45:40Z

Weaknesses